
CVE-2025-12139-WordPress-Integrate-Google-Drive-Exploit
Golang PoC exploit for CVE-2025-12139 targeting the Integrate Google Drive WordPress plugin. Extracts sensitive OAuth credentials (Client ID, Secret,…

Golang PoC exploit for CVE-2025-12139 targeting the Integrate Google Drive WordPress plugin. Extracts sensitive OAuth credentials (Client ID, Secret,…

Fast, accurate subdomain takeover scanner with zero false positives. Detects vulnerable subdomains, collects metadata (IP, CNAME, title, status…

Passive DNS server that detects exposed cloud storage buckets (AWS S3, GCP, Azure) by resolving DNS requests, tracing CNAME chains, and flagging…

Exploit for CVE-2018-20555: automated discovery and takeover of Twitter accounts via leaked API keys in vulnerable Social Network Tabs WordPress…

CVE-2024-4040 CrushFTP SSTI LFI & Auth Bypass | Full Server Takeover | Wordlist Support

Proof of concept for a critical Monnit Cloud account takeover (CVE-2025-50433), exploiting missing token-email validation in password reset and…

CVE-2025-5154: Proof-of-concept for unencrypted local storage of authentication tokens, PII, and KYC data in the PhonePe Android app, enabling…

Proof-of-concept exploit for CVE-2023-22515, a critical broken access control vulnerability in Confluence Server and Data Center, enabling…

Xboard / V2Board Unauth Account Takeover - Magic Link Token Leak (CVE-2026-39912)

Detect whether a Strapi instance is vulnerable to CVE-2026-27886 (unauthenticated boolean-oracle exfiltration of administrator secrets).

CVE-2020-35847, CVE-2020-35848 : Account Takeover

Improper Access Control in Mysterium Node before v1.36.0

Fast DNS takeover scanner that checks for missing hosted zones by querying nameservers and fingerprinting providers to identify vulnerable subdomains.

Multithreaded Plugin based vulnerability scanner for mass detection of web-based applications vulnerabilities

A phased, evasive Path Traversal + LFI scanning & exploitation tool in Python

Curated collection of top HackerOne bug bounty reports organized by vulnerability type and program, with scripts to fetch, deduplicate, and rank…

Multi-source subdomain enumeration tool with 50+ collection modules, DNS brute-force, passive DNS analysis, certificate transparency, search engine…

Field-validated offensive security skill pack with 169 techniques for reconnaissance and penetration testing. Covers CORS, SSRF, subdomain takeover,…